CVE-2023-26128
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published May 27, 2023
Updated: Jan 13, 2025
CWE ID 78
CWE ID 77
Summary
CVE-2023-26128 is a Command Injection vulnerability affecting all versions of the Node.js package "keep-module-latest." The issue arises due to insufficient input sanitization and the lack of checks and sandboxes in the installModule function. This flaw exposes the system or application to potential code injection attacks, allowing an attacker to execute arbitrary commands if they can run Node.js code within the target environment.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.